VULNERABILITY INTELLIGENCE
CVE-2016-10150
CVSS score10 HIGH
EPSS probability10.18%
CISA KEVNot currently listed
Published2017-02-06
Last modified2026-06-17
Description
Use-after-free vulnerability in the kvm_ioctl_create_device function in virt/kvm/kvm_main.c in the Linux kernel before 4.8.13 allows host OS users to cause a denial of service (host OS crash) or possibly gain privileges via crafted ioctl calls on the /dev/kvm device.